wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

NSE7 - Test - No. 1

Total questions: 109

Worksheet time: 3hrs 44mins

Name
Class
Date
1.

Multiple IPsec VPNs are formed between two hub-and-spokes groups, and site-to-site between Hub 1 and Hub 2. The administrator configured ADVPN on the dual regions topology. Which two statements are correct if a user in Toronto sends traffic to London? (Choose two.)

a)

Toronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.

b)

The first packets from Toronto to London are routed through Hub 1 then to Hub 2.

c)

London generates an IKE information message that contains the Toronto public IP address.

d)

Traffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN

2.

Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
FortiGate is not performing traffic shaping as expected, based on the policies shown in the exhibits.
To correct this traffic shaping issue on FortiGate, what configuration change must be made on which policy?

a)

The URL category must be specified on the traffic shaping policy.

b)

The shaper mode must be applied per-IP shaper on the traffic shaping policy.

c)

The web filter profile must be enabled on the firewall policy.

d)

The application control profile must be enabled on the firewall policy

3.

Which statement defines how a per-IP traffic shaper of 10 Mbps is applied to the entire network?

a)

The 10 Mbps bandwidth is shared equally among the IP addresses.

b)

Each IP is guaranteed a minimum 10 Mbps of bandwidth.

c)

FortiGate allocates each IP address a maximum 10 Mbps of bandwidth.

d)

A single user uses the allocated bandwidth divided by total number of users.

4.

Which three parameters are available to configure SD-WAN rules? (Choose three.)

a)

(Application signatures)

b)

(Internet service database - ISDB - address object)

c)

(Source and destination IP address)

d)

(Type of physical link connection)

5.

Which diagnostic command you can use to show interface-specific SLA logs for the last 10 minutes?

a)

diagnose sys virtual-wan-link health-check

b)
diagnose sys virtual-wan-link log
c)
diagnose sys virtual-wan-link sla-log
d)
diagnose sys virtual-wan-link intf-sla-log
6.

Which diagnostic command can you use to show the SD-WAN rules interface information and state?

a)
diagnose sys virtual-wan-link route-tag-list.
b)
diagnose sys virtual-wan-link service.
c)
diagnose sys virtual-wan-link member.
d)
diagnose sys virtual-wan-link neighbor.
7.

Exhibit A shows the performance SLA exhibit B shows the SD-WAN diagnostics output.
Based on the exhibits, which statement is correct?

a)

Port1 became dead because no traffic was offload through the egress of port1.

b)

SD-WAN member interfaces are affected by the SLA state of the inactive interface.

c)

Both SD-WAN member interfaces have used separate SLA targets.

d)

The SLA state of port1 is dead after five unanswered requests by the SLA servers.

8.

Which statement is correct about the SD-WAN and ADVPN?

a)
  • Spoke support dynamic VPN as a static interface.

b)

Dynamic VPN is not supported as an SD-WAN interface.

c)

ADVPN interface can be a member of SD-WAN interface.

d)
  • Hub FortiGate is limited to use ADVPN as SD-WAN member interface.

9.

Which two reasons make forward error correction (FEC) ideal to enable in a phase one VPN interface? (Choose two.)

a)

FEC is useful to increase speed at which traffic is routed through IPsec tunnels.

b)

FEC transmits the original payload in full to recover the error in transmission.

c)

FEC transmits additional packets as redundant data to the remote device.

d)

FEC improves reliability, which overcomes adverse WAN conditions such as noisy links.

e)
  • FEC reduces the stress on the remote device jitter buffer to reconstruct packet loss.

10.

Exhibit A shows the source NAT global setting and exhibit B shows the routing table on FortiGate. Based on the exhibits, which two statements about increasing the port2 interface priority to 20 are true? (Choose two.)

a)

All the existing sessions that do not use SNAT will be flushed and routed through port1.

b)

All the existing sessions will continue to use port2, and new sessions will use port1.

c)

All the existing sessions using SNAT will be flushed and routed through port1.

d)

All the existing sessions will be blocked from using port1 and port2.

11.

Which components make up the secure SD-WAN solution?

a)
FortiGate, FortiManager, FortiAnalyzer y FortiDeploy
b)
Application, antivirus, and URL, and SSL inspection
c)
Datacenter, branch offices, and public cloud
d)
Teléfono, RDSI y red de telecomunicaciones
12.

Which two statements about the status of the VPN tunnel are true? (Choose two.)

a)

There are separate virtual interfaces for each dial-up client.

b)

VPN static routes are prevented from populating the FortiGate routing table.

c)

FortiGate created a single IPsec virtual interface that is shared by all clients.

d)

100.64.3.1 is one of the remote IP address that comes through index interface 1.

13.

Exhibit A shows the SD-WAN rules and exhibit B shows the traffic logs. The SD-WAN traffic logs reflect how FortiGate processed traffic. Which two statements about how the configured SD-WAN rules are processing traffic are true? (Choose two.)

a)

The implicit rule overrides all other rules because parameters widely cover sources and destinations.

b)

SD-WAN rules are evaluated in the same way as firewall policies: from top to bottom.

c)

The All_Access_Rules rule load balances Vimeo application traffic among SD-WAN member interfaces.

d)

The initial session of an application goes through a learning phase in order to apply the correct rule

14.

What are the two minimum configuration requirements for an outgoing interface to be selected once the SD-WAN logical interface is enabled? (Choose two.)

a)

Specify outgoing interface routing cost.

b)

Configure SD-WAN rules interface preference.

c)

Select SD-WAN balancing strategy.

d)

Specify incoming interfaces in SD-WAN rules

15.

Based on the exhibit, which statement about FortiGate re-evaluating traffic is true?

a)

The type of traffic defined and allowed on firewall policy ID 1 is UDP.

b)

Changes have been made on firewall policy ID 1 on FortiGate.

c)

Firewall policy ID 1 has source NAT disabled.

d)

FortiGate has terminated the session after a change on policy ID 1.

16.

What are two reasons why FortiGate would be unable to complete the zero-touch provisioning process?(Choose two.)

a)

The FortiGate cloud key has not been added to the FortiGate cloud portal.

b)

FortiDeploy has connected with FortiGate and provided the initial configuration to contact FortiManager

c)

FortiGate has obtained a configuration from the platform template in FortiGate cloud.

d)

A factory reset performed on FortiGate

e)

The zero-touch provisioning process has completed internally, behind FortiGate

17.

Which two statements reflect the benefits of implementing the ADVPN solution to replace conventional VPN topologies? (Choose two.)

a)

It creates redundant tunnels between hub-and-spokes, in case failure takes place on the primary links.

b)

It dynamically assigns cost and weight between the hub and the spokes, based on the physical distance.

c)

It ensures that spoke-to-spoke traffic no longer needs to flow through the tunnels through the hub.

d)

It provides direct connectivity between all sites by creating on-demand tunnels between spokes.

18.

Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)

a)
set cost 15.
b)
set source 100.64.1.1.
c)
set priority 10
d)
set load-balance-mode source-ip-based
19.

Which two statements about the debug output are correct? (Choose two.)

a)

The debug output shows per-IP shaper values and real-time readings.

b)

This traffic shaper drops traffic that exceeds the set limits.

c)

Traffic being controlled by the traffic shaper is under 1 Kbps.

d)

FortiGate provides statistics and reading based on historical traffic logs.

20.
In the default SD-WAN minimum configuration, which two statements are correct when traffic matches the default implicit SD-WAN rule? (Choose two.)
a)
Traffic has matched none of the FortiGate policy routes.
b)
Matched traffic failed RPF and was caught by the rule
c)
The FIB lookup resolved interface was the SD-WAN interface
d)
An absolute SD-WAN rule was defined and matched traffic
21.
Which statement about the trace evaluation by FortiGate is true?
a)
Packets exceeding the configured maximum concurrent connection limit are denied by the per-IP shaper
b)
The packet exceeded the configured bandwidth and was dropped based on the priority configuration
c)
The packet exceeded the configured maximum bandwidth and was dropped by the shared shaper
d)
Packets exceeding the configured concurrent connection limit are dropped based on the priority configuration
22.
FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN. Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)
a)
Specify a unique peer ID for each dial-up VPN interface.
b)
Use different proposals are used between the interfaces
c)
Configure the IKE mode to be aggressive mode.
d)
Use unique Diffie Hellman groups on each VPN interface
23.
Exhibit A shows the firewall policy and exhibit B shows the traffic shaping policy. The traffic shaping policy is being applied to all outbound traffic; however, inbound traffic is not being evaluated by the shaping policy. Based on the exhibits, what configuration change must be made in which policy so that traffic shaping can be applied to inbound traffic?
a)
The guaranteed-10mbps option must be selected as the per-IP shaper option.
b)
The guaranteed-10mbps option must be selected as the reverse shaper option.
c)
A new firewall policy must be created and SD-WAN must be selected as the incoming interface.
d)
The reverse shaper option must be enabled and a traffic shaper must be selected
24.
What must you configure to enable ADVPN?
a)
ADVPN should only be enabled on unmanaged FortiGate devices
b)
Each VPN device has a unique pre-shared key configured separately on phase one
c)
The protected subnets should be set to address object to all (0.0.0.0/0).
d)
On the hub VPN, only the device needs additional phase one settings
25.
Which two statements describe how IPsec phase 1 main mode id different from aggressive mode when performing IKE negotiation? (Choose two.)
a)
A peer ID is included in the first packet from the initiator, along with suggested security policies
b)
XAuth is enabled as an additional level of authentication, which requires a username and password
c)
A total of six packets are exchanged between an initiator and a responder instead of three packets
d)
The use of Diffie Hellman keys is limited by the responder and needs initiator acceptance
26.
What are two benefits of using FortiManager to organize and manage the network for a group of FortiGate devices? (Choose two.)
a)
It simplifies the deployment and administration of SD-WAN on managed FortiGate devices.
b)
It improves SD-WAN performance on the managed FortiGate devices
c)
It sends probe signals as health checks to the beacon servers on behalf of FortiGate
d)
It acts as a policy compliance entity to review all managed FortiGate devices
e)
It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server
27.
What would best describe the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?
a)
Per-IP shaping mode
b)
Shared policy shaping mode
c)
Interface-based shaping mode
d)
Reverse policy shaping mode
28.
Exhibit A, which shows the SD-WAN performance SLA and exhibit B shows the health of the participating SD-WAN members. Based on the exhibits, which statement is correct?
a)
The dead member interface stays unavailable until an administrator manually brings the interface back
b)
Port2 needs to wait 500 milliseconds to change the status from alive to dead
c)

Static routes using port2 are active in the routing table.

d)

FortiGate has not received three consecutive requests from the SLA server configured for port2.

29.
What is the lnkmtd process responsible for?
a)
Flushing route tags addresses
b)
Monitoring links for any bandwidth saturation
c)
Logging interface quality information
d)
Processing performance SLA probes
30.
Which statement reflects how BGP tags work with SD-WAN rules?
a)
VPN topologies are formed using only BGP dynamic routing with SD-WAN
b)
Route tags are used for a BGP community and the SD-WAN rules are assigned the same tag
c)
BGP tags require that the adding of static routes be enabled on all ADVPN interfaces
d)
BGP tags match the SD-WAN rule based on the order that these rules were installed
31.
Which statement about using BGP routes in SD-WAN is true?
a)
Adding static routes must be enabled on all ADVPN interfaces
b)
VPN topologies must be form using only BGP dynamic routing with SD-WAN
c)
Learned routes can be used as dynamic destinations in SD-WAN rules
d)
Dynamic routing protocols can be used only with non-encrypted traffic
32.
An administrator is troubleshooting VoIP quality issues that occur when calling external phone numbers. The SD-WAN interface on the edge FortiGate is configured with the default settings, and is using two upstream links. One link has random jitter and latency issues, and is based on a wireless connection. Which two actions must the administrator apply simultaneously on the edge FortiGate to improve VoIP quality using SD-WAN rules? (Choose two.)
a)
Select the corresponding SD-WAN balancing strategy in the SD-WAN rule.
b)
Choose the suitable interface based on the interface cost and weight.
c)
Use the performance SLA targets to detect latency and jitter instantly.
d)
Place the troublesome link at the top of the interface preference list.
e)
Configure an SD-WAN rule to load balance all traffic without VoIP
33.
Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN interface and the static routes configuration. Port1 and port2 are member interfaces of the SD-WAN, and port2 becomes a dead member after reaching the failure thresholds. Which statement about the dead member is correct?
a)
Port2 might become alive when a single response is received from an SLA server.
b)
Dead members require manual administrator access to bring them back alive
c)
Subnets 100.64.1.0/24 and 172.20.0.0/16 are reachable only through port1
d)
SD-WAN interface becomes disabled and port1 becomes the WAN interface
34.
What are two roles that SD-WAN orchestrator plays when it works with FortiManager? (Choose two.)
a)
It configures and monitors SD-WAN networks on FortiGate devices that are managed by FortiManager.
b)
It acts as a standalone device to assist FortiManager to manage SD-WAN interfaces on the managed FortiGate devices
c)
It acts as a hub FortiGate with an SD-WAN interface enabled and managed along with other FortiGate devices by FortiManager
d)
It acts as an application that is released and signed by Fortinet to run as a part of management extensions on FortiManager
35.
Which statement about the command route-tag in the SD-WAN rule is true?
a)
It ensures route tags match the SD-WAN rule based on the rule order
b)
It tags each route and references the tag in the routing table
c)
It enables the SD-WAN rule to load balance and assign traffic with a route tag.
d)
It uses route tags for a BGP community and assigns the SD-WAN rules with same tag
36.

Which two configuration tasks are required to use SD-WAN? (Choose two.)

a)

Add one or more members to an SD-WAN zone.

b)

Configure at least one firewall policy for SD-WAN traffic.

c)

Specify the outgoing interface routing cost.

d)

Specify the incoming interfaces in SD-WAN rules.

37.

A FortiGate device has the following LDAP configuration:
The administrator executed the ‘dsquery’ command in the Windows LDAp server 10.0.1.10, and got the following output: >dsquery user –samid administrator “CN=Administrator, CN=Users, DC=trainingAD, DC=training, DC=lab” Based on the output, what FortiGate LDAP setting is configured incorrectly?

a)
cnid
b)
username
c)
password
d)
dn
38.

An administrator has configured a dial-up IPsec VPN with one phase 2, extended authentication (XAuth) and IKE mode configuration. The administrator has also enabled the IKE real time debug: diagnose debug application ike-1 diagnose debug enable

In which order is each step and phase displayed in the debug output each time a new dialup user is connecting to the VPN?

a)
Fase 1; Configuración del modo IKE; XAuth; fase 2.
b)
Fase 1; XAuth; Configuración del modo IKE; Fase 2.
c)
Fase 1; XAuth; Fase 2; Configuración del modo IKE.
d)
Fase 1; Configuración del modo IKE; Fase 2; XAuth.
39.

Which the following events can trigger the election of a new primary unit in a HA cluster? (Choose two.)

a)

Primary unit stops sending HA heartbeat keepalives

b)

The FortiGuard license for the primary unit is updated

c)

One of the monitored interfaces in the primary unit is disconnected

d)

A secondary unit is removed from the HA cluster

40.

An administrator has enabled HA session synchronization in a HA cluster with two members. Which flag is added to a primary unit’s session to indicate that it has been synchronized to the secondary unit?

a)
redir.
b)
dirty.
c)
synced.
d)
nds
41.

Examine the output of the ‘get router info ospf interface’ command shown in the exhibit; then answer the question below. Which statements are true regarding the above output? (Choose two.)

a)

The port4 interface is connected to the OSPF backbone area

b)

The local FortiGate has been elected as the OSPF backup designated router.

c)

There are at least 5 OSPF routers connected to the port4 network.

d)

Two OSPF routers are down in the port4 network.

42.

Examine the output of the 'diagnose debug rating' command shown in the exhibit; then answer the question below.Which statement are true regarding the output in the exhibit? (Choose two.)

a)

There are three FortiGuard servers that are not responding to the queries sent by the FortiGate

b)

The TZ value represents the delta between each FortiGuard server's time zone and the FortiGate's time zone

c)

FortiGate will send the FortiGuard queries to the server with highest weight

d)

A server's round trip delay (RTT) is not used to calculate its weight.

43.

An administrator cannot connect to the GIU of a FortiGate unit with the IP address 10.0.1.254. The administrator runs the debug flow while attempting the connection using HTTP. The output of the debug flow is shown in the exhibit: Based on the error displayed by the debug flow, which are valid reasons for this problem? (Choose two.)

a)

HTTP administrative access is disabled in the FortiGate interface with the IP address 10.0.1.254.

b)

Redirection of HTTP to HTTPS administrative access is disabled.

c)

HTTP administrative access is configured with a port number different than 80.

d)

The packet is denied because of reverse path forwarding check.

44.

A FortiGate is rebooting unexpectedly without any apparent reason. What troubleshooting tools could an administrator use to get more information about the problem? (Choose two.)

a)
Firewall monitor.
b)
Policy monitor.
c)
Logs.
d)
Crashlogs.
45.

Examine the output of the ‘diagnose ips anomaly list’ command shown in the exhibit; then answer the question below. Which IP addresses are included in the output of this command?

a)

Those whose traffic matches a DoS policy.

b)

Those whose traffic matches an IPS sensor

c)

Those whose traffic exceeded a threshold of a matching DoS policy

d)

Those whose traffic was detected as an anomaly by an IPS sensor.

46.

Examine the following partial output from a sniffer command; then answer the question below.What is the meaning of the packets dropped counter at the end of the sniffer?

a)

Number of packets that didn’t match the sniffer filter

b)

Number of total packets dropped by the FortiGate

c)

Number of packets that matched the sniffer filter and were dropped by the FortiGate.

d)

Number of packets that matched the sniffer filter but could not be captured by the sniffer.

47.

Which of the following statements are true about FortiManager when it is deployed as a local FDS? (Choose two.)

a)

Caches available firmware updates for unmanaged devices..

b)

Can be configured as an update server, or a rating server, but not both

c)

Supports rating requests from both managed and unmanaged devices

d)

Provides VM license validation services.

48.

Which statement is true regarding File description (FD) conserve mode?

a)

IPS inspection is affected when FortiGate enters FD conserve mode.

b)

A FortiGate enters FD conserve mode when the amount of available, description is less than 5%.

c)

FD conserve mode affects all daemons running on the device.

d)

Restarting the WAD process is required to leave FD conserve mode.

49.

A FortiGate's portl is connected to a private network. Its port2 is connected to the Internet. Explicit web proxy is enabled in port1 and only explicit web proxy users can access the Internet. Web cache is NOT enabled. An internal web proxy user is downloading a file from the Internet via HTTP. Which statements are true regarding the two entries in the FortiGate session table related with this traffic? (Choose two.)

a)

Both session have the local flag on.

b)

The destination IP addresses of both sessions are IP addresses assigned to FortiGate's interfaces.

c)

One session has the proxy flag on, the other one does not.

d)

One of the sessions has the IP address of port2 as the source IP address.

50.

Four FortiGate devices configured for OSPF connected to the same broadcast domain. The first unit is elected as the designated router The second unit is elected as the backup designated router Under normal operation, how many OSPF full adjacencies are formed to each of the other two units?

a)
1
b)
2
c)
3
d)
4
51.

What configuration changes can reduce the memory utilization in a FortiGate? (Choose two.)

a)

Reduce the session time to live.

b)

Increase the TCP session timers.

c)

Increase the FortiGuard cache time to live.

d)

Reduce the maximum file size to inspect.

52.

View the exhibit, which contains the output of a debug command, and then answer thequestion below. Which of the following statements about the exhibit are true? (Choose two.)

a)
In the network on port4, two OSPF routers are down.
b)
Port4 is connected to the OSPF backbone area.
c)

The local FortiGate´s OSPF router ID is 0.0.0.4

d)
The local FortiGate has been elected as the OSPF backup designated router.
53.
How does FortiManager handle FortiGuard requests from FortiGate devices, when it is configured as a local FDS?
a)
FortiManager can download and maintain local copies of FortiGuard databases.
b)
FortiManager supports only FortiGuard push to managed devices.
c)
FortiManager will respond to update requests only if they originate from a managed device.
d)
FortiManager does not support rating requests.
54.
View the exhibit, which contains the output of a real-time debug, and then answer the question below. Which of the following statements is true regarding this output? (Choose two.)
a)
This web request was inspected using the root web filter profile.
b)
FortiGate found the requested URL in its local cache.
c)
The requested URL belongs to category ID 52.
d)
The web request was allowed by FortiGate.
55.
What is the purpose of an internal segmentation firewall (ISFW)?
a)
It inspects incoming traffic to protect services in the corporate DMZ.
b)
It is the first line of defense at the network perimeter.
c)
It splits the network into multiple security segments to minimize the impact of breaches.
d)
It is an all-in-one security appliance that is placed at remote sites to extend the enterprise network.
56.
Which of the following statements are correct regarding application layer test commands? (Choose two.)
a)
They are used to filter real-time debugs.
b)
They display real-time application debugs.
c)
Some of them display statistics and configuration information about a feature or process.
d)
Some of them can be used to restart an application
57.
When using the SSL certificate inspection method for HTTPS traffic, how does FortiGate filter web requests when the browser client does not provide the server name indication (SNI)?
a)

FortiGate uses the Issued To: field in the server´s certificate.

b)
FortiGate switches to the full SSL inspection method to decrypt the data.
c)
FortiGate blocks the request without any further inspection.
d)

FortiGate uses the requested URL from the user´s web browser.

58.
What global configuration setting changes the behavior for content-inspected traffic while FortiGate is in system conserve mode?
a)
av-failopen
b)
mem-failopen
c)
utm-failopen
d)
ips-failopen
59.

View the exhibit, which contains the output of a BGP debug command, and then answer the question below. Which of the following statements about the exhibit are true? (Choose two.)

a)
For the peer 10.125.0.60, the BGP state of is Established.
b)
The local BGP peer has received a total of three BGP prefixes.
c)
Since the BGP counters were last reset, the BGP peer 10.200.3.1 has never been down.
d)
The local BGP peer has not established a TCP session to the BGP peer 10.200.3.1.
60.
View the exhibit, which contains the output of a web diagnose command, and then answer the question below. Which one of the following statements explains why the cache statistics are all zeros?
a)
The administrator has reallocated the cache memory to a separate process.
b)
There are no users making web requests.
c)

The FortiGuard web filter cache is disabled in the FortiGate´s configuration.

d)
FortiGate is using a flow-based web filter and the cache applies only to proxy-based inspection.
61.

View the exhibit, which contains a partial output of an IKE real-time debug, and then answer the question below. Based on the debug output, which phase-1 setting is enabled in the configuration of this VPN?

a)
auto-discovery-sender
b)
auto-discovery-forwarder
c)
auto-discovery-shortcut
d)
auto-discovery-receiver
62.
View the global IPS configuration, and then answer the question below. Which of the following statements is true regarding this configuration?
a)
IPS will scan every byte in every session.
b)
FortiGate will spawn IPS engine instances based on the system load.
c)
New packets will be passed through without inspection if the IPS socket buffer runs out of memory.
d)
IPS will use the faster matching algorithm which is only available for units with more than 4 GB memory.
63.

View the following FortiGate configuration. All traffic to the Internet currently egresses from port1. The exhibit shows partial session information for Internet traffic from a user on the internal network: If the priority on route ID 1 were changed from 5 to 20, what would happen to traffic matching that user´s session?

a)
The session would remain in the session table, and its traffic would still egress from port1.
b)
The session would remain in the session table, but its traffic would now egress from both port1 and port2.
c)
The session would remain in the session table, and its traffic would start to egress from port2.
d)
The session would be deleted, so the client would need to start a new session.
64.
View the exhibit, which contains the output of a diagnose command, and then answer the question below. Which statements are true regarding the output in the exhibit? (Choose two.)
a)
FortiGate will probe 121.111.236.179 every fifteen minutes for a response.
b)
Servers with the D flag are considered to be down.
c)
Servers with a negative TZ value are experiencing a service outage.
d)

FortiGate used 209.222.147.36 as the initial server to validate its contract.

65.
What does the dirty flag mean in a FortiGate session?
a)
Traffic has been blocked by the antivirus inspection.
b)
The next packet must be re-evaluated against the firewall policies.
c)
The session must be removed from the former primary unit after an HA failover.
d)
Traffic has been identified as from an application that is not allowed.
66.

Examine the IPsec configuration shown in the exhibit; then answer the question below. An administrator wants to monitor the VPN by enabling the IKE real time debug using these commands: diagnose vpn ike log-filter src-addr4 10.0.10.1 diagnose debug application ike -1 diagnose debug enable The VPN is currently up, there is no traffic crossing the tunnel and DPD packets are being interchanged between both IPsec gateways. However, the IKE real time debug does NOT show any output. Why isn´t there any output?

a)
The IKE real time shows the phases 1 and 2 negotiations only. It does not show any more output once the tunnel is up.
b)

The log-filter setting is set incorrectly. The VPN´s traffic does not match this filter.

c)
The IKE real time debug shows the phase 1 negotiation only. For information after that, the administrator must use the IPsec real time debug instead: diagnose debug application ipsec -1.
d)
The IKE real time debug shows error messages only. If it does not provide any output, it indicates that the tunnel is operating normally.
67.
Which of the following statements are true regarding the SIP session helper and the SIP application layer gateway (ALG)? (Choose three.)
a)
SIP session helper runs in the kernel; SIP ALG runs as a user space process.
b)
SIP ALG supports SIP HA failover; SIP helper does not.
c)
SIP ALG supports SIP over IPv6; SIP helper does not.
d)
SIP ALG can create expected sessions for media traffic; SIP helper does not.
e)
SIP helper supports SIP over TCP and UDP; SIP ALG supports only SIP over UDP.
68.

A FortiGate device has the following LDAP configuration. The administrator executed the "dsquery" command in the Windows LDAp server 10.0.1.10, and got the following output: >dsquery user ""samid administrator "CN=Administrator, CN=Users, DC=trainingAD, DC=training, DC=lab" Based on the output, what FortiGate LDAP setting is configured incorrectly?

a)
cnid.
b)
username.
c)
password.
d)
dn.
69.
Which of the following statements is true regarding a FortiGate configured as an explicit web proxy?
a)
FortiGate limits the number of simultaneous sessions per explicit web proxy user. This limit CANNOT be modified by the administrator.
b)
FortiGate limits the total number of simultaneous explicit web proxy users.
c)
FortiGate limits the number of simultaneous sessions per explicit web proxy user. The limit CAN be modified by the administrator.
d)
FortiGate limits the number of workstations that authenticate using the same web proxy user credentials. This limit CANNOT be modified by the administrator.
70.

A corporate network allows Internet Access to FSSO users only. The FSSO user student does not have Internet access after successfully logged into the Windows AD network. The output of the "diagnose debug authd fsso list" command does not show student as an active FSSO user. Other FSSO users can access the Internet without problems. What should the administrator check? (Choose two.)

a)

The user student must not be listed in the CA´s ignore user list.

b)
The user student must belong to one or more of the monitored user groups.
c)

The student workstation´s IP subnet must be listed in the CA´s trusted list.

d)

At least one of the student´s user groups must be allowed by a FortiGate firewall policy.

71.
An administrator has decreased all the TCP session timers to optimize the FortiGate memory usage. However, after the changes, one network application started to have problems. During the troubleshooting, the administrator noticed that the FortiGate deletes the sessions after the clients send the SYN packets, and before the arrival of the SYN/ACKs. When the SYN/ACK packets arrive to the FortiGate, the unit has already deleted the respective sessions. Which TCP session timer must be increased to fix this problem?
a)
TCP half open.
b)
TCP half close.
c)
TCP time wait.
d)
TCP session time to live.
72.
An administrator is running the following sniffer in a FortiGate: diagnose sniffer packet any "host 10.0.2.10" 2 What information is included in the output of the sniffer? (Choose two.)
a)
Ethernet headers.
b)
IP payload.
c)
IP headers.
d)
Port names.
73.
Examine the partial output from two web filter debug commands; then answer the question below: Based on the above outputs, which is the FortiGuard web filter category for the web site www.fgt99.com?
a)
Finance and banking
b)
General organization.
c)
Business.
d)
Information technology.
74.

Examine the output of the "get router info bgp summary" command shown in the exhibit; then answer the question below. Which statements are true regarding the output in the exhibit? (Choose two.)

a)
BGP state of the peer 10.125.0.60 is Established.
b)
BGP peer 10.200.3.1 has never been down since the BGP counters were cleared.
c)
Local BGP peer has not received an OpenConfirm from 10.200.3.1.
d)
The local BGP peer has received a total of 3 BGP prefixes.
75.

A FortiGate is configured as an explicit web proxy. Clients using this web proxy are reposting DNS errors when accessing any website. The administrator executes the following debug commands and observes that the n-dns-timeout counter is increasing: What should the administrator check to fix the problem? (Choose Two.)

a)
The connectivity between the FortiGate unit and the DNS server.
b)
The connectivity between the client workstations and the DNS server.
c)
That DNS traffic from client workstations is allowed by the explicit web proxy policies.
d)
That DNS service is enabled in the explicit web proxy interface.
76.
Which real time debug should an administrator enable to troubleshoot RADIUS authentication problems?
a)
Diagnose debug application radius -1.
b)
Diagnose debug application fnbamd -1.
c)
Diagnose authd console ""log enable.
d)
Diagnose radius console ""log enable.
77.

Examine the output of the "diagnose sys session list expectation" command shown in the exhibit; than answer the question below. Which statement is true regarding the session in the exhibit?

a)
It was created by the FortiGate kernel to allow push updates from FotiGuard.
b)
It is for management traffic terminating at the FortiGate.
c)
It is for traffic originated from the FortiGate.
d)
It was created by a session helper or ALG.
78.

An administrator has configured a FortiGate device with two VDOMs: root and internal. The administrator has also created and inter-VDOM link that connects both VDOMs. The objective is to have each VDOM advertise some routes to the other VDOM via OSPF through the inter-VDOM link. What OSPF configuration settings must match in both VDOMs to have the OSPF adjacency successfully forming? (Choose three.)

a)
Router ID.
b)
OSPF interface area.
c)
OSPF interface cost.
d)
OSPF interface MTU.
e)
Interface subnet mask.
79.

An administrator has configured a dial-up IPsec VPN with one phase 2, extended authentication (XAuth) and IKE mode configuration. The administrator has also enabled the IKE real time debug: diagnose debug application ike-1 diagnose debug enable In which order is each step and phase displayed in the debug output each time a new dial-up user is connecting to the VPN?

a)
Phase1; IKE mode configuration; XAuth; phase 2.
b)
Phase1; XAuth; IKE mode configuration; phase2.
c)
Phase1; XAuth; phase 2; IKE mode configuration.
d)
Phase1; IKE mode configuration; phase 2; XAuth.
80.
Two independent FortiGate HA clusters are connected to the same broadcast domain. The administrator has reported that both clusters are using the same HA virtual MAC address. This creates a duplicated MAC address problem in the network. What HA setting must be changed in one of the HA clusters to fix the problem?
a)
Group ID.
b)
Group name.
c)
Session pickup.
d)
Gratuitous ARPs.
81.
When does a RADIUS server send an Access-Challenge packet?
a)
The server does not have the user credentials yet.
b)
The server requires more information from the user, such as the token code for two-factor authentication.
c)
The user credentials are wrong.
d)
The user account is not found in the server.
82.
The logs in a FSSO collector agent (CA) are showing the following error: failed to connect to registry: PIKA1026 (192.168.12.232) What can be the reason for this error?
a)
The CA cannot resolve the name of the workstation.
b)
The FortiGate cannot resolve the name of the workstation.
c)
The remote registry service is not running in the workstation 192.168.12.232.
d)
The CA cannot reach the FortiGate with the IP address 192.168.12.232.
83.

Examine the output of the "get router info ospf neighbor" command shown in the exhibit; then answer the question below. Which statements are true regarding the output in the exhibit? (Choose two.)

a)
The interface ToRemote is OSPF network type point-to-point.
b)
The OSPF router with the ID 0.0.0.2 is the designated router for the ToRemote network.
c)
The local FortiGate is the backup designated router for the wan1 network.
d)
The OSPF routers with the IDs 0.0.0.69 and 0.0.0.117 are both designated routers for the wan1 network.
84.

A FortiGate has two default routes: All Internet traffic is currently using port1. The exhibit shows partial information for one sample session of Internet traffic from an internal user: What would happen with the traffic matching the above session if the priority on the first default route (IDd1) were changed from 5 to 20?

a)
Session would remain in the session table and its traffic would keep using port1 as the outgoing interface.
b)
Session would remain in the session table and its traffic would start using port2 as the outgoing interface.
c)
Session would be deleted, so the client would need to start a new session.
d)
Session would remain in the session table and its traffic would be shared between port1 and port2.
85.
What events are recorded in the crashlogs of a ForitGate device? (Choose two.)
a)
A process crash.
b)
Configuration changes.
c)
Changes in the status of any of the FortiGuard licenses.
d)
System entering to and leaving from the proxy conserve mode.
86.

Examine the following partial outputs from two routing debug commands; then answer the question below: Why the default route using port2 is not displayed in the output of the second command?

a)
It has a lower priority than the default route using port1.
b)
It has a higher priority than the default route using port1.
c)
It has a higher distance than the default route using port1.
d)

It is disabled in the FortiGate configuration.

87.
Which three conditions are required for two FortiGate devices to form an OSPF adjacency? (Choose three.)
a)
OSPF interface network types match.
b)
OSPF router IDs are unique
c)
OSPF interface priority settings are unique.
d)
Authentication settings match.
e)
OSPF link costs match.
88.

The administrator does not have access to the remote gateway. Based on the debug output, which configuration change can the administrator make to the local gateway to resolve the phase 1 negotiation error?

a)
In the phase 1 network configuration, set the IKE version to 2.
b)
In the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.
c)
In the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.
d)
In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.
89.
Refer to the exhibit, which shows the output of a web filtering diagnose command. Which configuration change would result in non-zero results in the cache statistics section?
a)
set server-type rating under config system central-management
b)
set webfilter-cache enable under config system fortiguard
c)
set webfilter-force-off disable under config system fortiguard
d)
set ngfw-mode policy-based under config system settings
90.

Refer to the exhibits, which show the configuration on FortiGate and partial session information for internet traffic from a user on the internal network. If the priority on route ID 2 were changed from 10 to 0, what would happen to traffic matching that user session?

a)
The session would remain in the session table, but its traffic would now egress from both port1 and port2.
b)
The session would remain in the session table, and its traffic would egress from port2.
c)
The session would be deleted, and the client would need to start a new session.
d)
The session would remain in the session table, and its traffic would egress from port1.
91.

Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network An administrator would like to test session failover between the two service provider connections. What changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)

a)
Configure set snat-route-change enable.
b)
Change the priority of the port2 static route to 5.
c)
Change the priority of the port1 static route to 11.
d)
unset snat-route-change to return it to the default setting.
92.
Examine the output of the ‘get router info bgp summary’ command shown in the exhibit; then answer the question below . Which statement can explain why the state of the remote BGP peer 10.200.3.1 is Connect?
a)
The local peer is receiving the BGP keepalives from the remote peer but it has not received any BGP prefix yet.
b)
The TCP session for the BGP connection to 10.200.3.1 is down.
c)
The local peer has received the BGP prefixed from the remote peer.
d)
The local peer is receiving the BGP keep alive from the remote peer but it has not received the Open Confirm yet.
93.
The CLI command set intelligent-mode controls the IPS engine's adaptive scanning behavior. Which of the following statements describes IPS adaptive scanning?
a)
Determines the optimal number of IPS engines required based on system load.
b)
Downloads signatures on demand from FDS based on scanning requirements.
c)
Determines when it is secure enough to stop scanning session traffic.
d)
Choose a matching algorithm based on available memory and the type of inspection being performed.
94.
An administrator has configured the following CLI script on FortiManager, which failed to apply any changes to the managed device after being executed. Why didn't the script make any changes to the managed device?
a)
Commands that start with the # sign are not executed.
b)
CLI scripts will add objects only if they are referenced by policies.
c)
Incomplete commands are ignored in CLI scripts.
d)
Static routes can only be added using TCL scripts.
95.

Refer to the exhibit, which contains a partial web filter profile configuration. Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?

a)
FortiGate will exempt the connection based on the Web Content Filter configuration.
b)
FortiGate will block the connection based on the URL Filter configuration.
c)
FortiGate will allow the connection based on the FortiGuard category based filter configuration.
d)
FortiGate will block the connection as an invalid URL.
96.
Which configuration can be used to reduce the number of BGP sessions in an IBGP network?
a)
Neighbor range
b)
Route reflector
c)
Next-hop-self
d)
Neighbor group
97.
View the exhibit, which contains the output of get sys ha status, and then answer the question below. Which statements are correct regarding the output? (Choose two.)
a)

The slave configuration is synchronized with the master.

b)

port7 is used as the HA heartbeat on all devices in the cluster.

c)

Master is selected based on the priority configured under config system ha.

d)

The HA management IP is 169.254.0.2.

98.

Examine the output from the BGP real time debug shown in the exhibit, then the answer the question below: Which statements are true regarding the output in the exhibit? (Choose two.)

a)
BGP peers have successfully interchanged Open and Keepalive messages.
b)
The state of the remote BGP peer is OpenConfirm.
c)
Local BGP peer received a prefix for a default route.
d)
The state of the remote BGP peer will go to Connect after it confirms the received prefixes.
99.

Which two protocols in the IPsec suite are most used for authentication and encryption? (Choose two.)

a)

Encapsulating Security Payload (ESP)

b)

Secure Shell (SSH)

c)

Internet Key Exchange (IKE)

d)

Security Association (SA)

100.

Which two settings can you configure to speed up routing convergence in BGP? (Choose two.)

a)

update-source

b)

set-route-tag

c)

holdtime-timer

d)

link-down-failover

101.

Exhibit A shows the configuration for an SD-WAN rule and exhibit B shows the respective rule status, the routing table, and the member status. The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule. Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?

a)

The traffic will be load balanced across all three overlays.

b)

The traffic will be routed over T_INET_0_0.

c)

The traffic will be routed over T_MPLS_0.

d)
  • The traffic will be routed over T_INET_1_0.

102.

View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the question below. ike 0: comes 10.0.0.2:500->10.0.0.1:500, ifindex=7.... ike 0: IKEv1 exchange=Aggressive id=baf47d0988e9237f/2f405ef3952f6fda len=430 ike 0: in BAF47D0988E9237F2F405EF3952F6FDA0110040000000000000001AE0400003C0000000100000001000000300101000 ike 0:RemoteSite:4: initiator: aggressive mode get 1st response... ike 0:RemoteSite:4: VID RFC 3947 4A131c81070358455C5728F20E95452F ike 0:RemoteSite:4: VID DPD AFCAD71368A1F1C96B8696FC77570100 ike 0:RemoteSite:4: VID FORTIGATE 8299031757A36082C6A621DE000502D7 ike 0:RemoteSite:4: peer is FortiGate/Fortios (v5 b727) ike 0:RemoteSite:4: VID FRAGMENTATION 4048B7D56EBCE88525E7DE7F00D6C2D3 ike 0:RemoteSite:4: VID FRAGMENTATION 4048B7D56EBCE88525E7DE7F00D6C2D3C0000000 ike 0:RemoteSite:4: received peer identifier FQDN "˜remore"™ ike 0:RemoteSite:4: negotiation result ike 0:RemoteSite:4: proposal id = 1: ike 0:RemoteSite:4: protocol id = ISAKMP: ike 0:RemoteSite:4: trans_id = KEY_IKE. ike 0:RemoteSite:4: encapsulation = IKE/none ike 0:RemoteSite:4: type=OAKLEY_ENCRYPT_ALG, val=AES_CBC, key ""len=128 ike 0:RemoteSite:4: type=OAKLEY_HASH_ALG, val=SHA. ike 0:RemoteSite:4: type-AUTH_METHOD, val=PRESHARED_KEY. ike 0:RemoteSite:4: type=OAKLEY_GROUP, val=MODP1024. ike 0:RemoteSite:4: ISAKMP SA lifetime=86400 ike 0:RemoteSite:4: ISAKMP SA baf47d0988e9237f/2f405ef3952f6fda key 16: B25B6C9384D8BDB24E3DA3DC90CF5E73 ike 0:RemoteSite:4: PSK authentication succeeded ike 0:RemoteSite:4: authentication OK ike 0:RemoteSite:4: add INITIAL-CONTACT ike 0:RemoteSite:4: enc BAF47D0988E9237F405EF3952F6FDA081004010000000000000080140000181F2E48BFD8E9D603F ike 0:RemoteSite:4: out BAF47D0988E9237F405EF3952F6FDA08100401000000000000008C2E3FC9BA061816A396F009A12 ike 0:RemoteSite:4: sent IKE msg (agg_i2send): 10.0.0.1:500-10.0.0.2:500, len=140, id=baf47d0988e9237f/2 ike 0:RemoteSite:4: established IKE SA baf47d0988e9237f/2f405ef3952f6fda
Which statements about this debug output are correct? (Choose two.)

a)

The remote gateway IP address is 10.0.0.1.

b)

It shows a phase 1 negotiation.

c)

 The negotiation is using AES128 encryption with CBC hash.

d)

The initiator has provided remote as its IPsec peer ID.

103.

Which three protocols are available only on the command line to configure as performance SLA status check? (Choose three.)

a)

smtp

b)

tcp-echo

c)

twamp

d)

udp-echo

e)

icmp

104.

What are two reasons why it is effective to implement the internet service database (ISDB) in an SD-WAN rule? (Choose two)

a)

The ISDB is dynamically updated and reduces administrative overhead.

b)

The ISDB applies rules to traffic from specific sources, based on application type.

c)

The ISDB requires application control to maintain signatures and perform load-balancing.

d)

The ISDB contains the IP addresses and port ranges of well-known destinations.

105.

Refer to the exhibit. Based on the exhibit, which two actions does FortiGate perform on traffic passing through the SD-WAN member port2? (Choose two.)

a)

FortiGate performs routing lookups for new sessions only after a route change.

b)

FortiGate marks the routing information on existing sessions as persistent.

c)

FortiGate flushes all routing information from the session table after a route change.

d)

FortiGate always blocks all traffic after a route change.

106.

Refer to the exhibits. ExhibitA shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate. Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?

a)

port2 is referenced in a static route.

b)

port1 is assigned a manual IP address.

c)

port1 and port2 are not administratively down.

d)

port1 is referenced in a firewall policy.

107.

Refer to exhibits. Exhibit A shows the firewall policy and exhibit B shows the traffic shaping policy. The traffic shaping policy is being applied to all outbound traffic; however, inbound traffic is not being evaluated by the shaping policy. Based on the exhibits, what configuration change must be made in which policy so that traffic shaping can be applied to inbound traffic?

a)

Create a new firewall policy, and the select the SD-WAN zone as Incoming Interface.

b)

In the traffic shaping policy, select Assign Shaping Class ID as Action.

c)

In the firewall policy, select Proxy-based as Inspection Mode.

d)

In the traffic shaping policy, enable Reverse shaper, and then select the traffic shaper to use.

108.

Refer to the exhibit, which shows the output of get system ha status. NGFW-1 and NGFW-2 have been up for a week. Which two statements about the output are true? (Choose two.)

a)

If FGVM...649 is rebooted, FGVM...650 will become the primary and retain that role, even after FGVM...649 rejoins the cluster. 

b)

 If no action is taken, the primary FortiGate will leave the cluster due to the current sync status.

c)

If port7 becomes disconnected on the secondary, both FortiGate devices will elect itself the primary.

d)

If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset.

109.
a)

The slave configuration is not synchronized with the master.

b)

The HA management IP is 169.254.0.2.

c)

Master is selected because it is the only device in the cluster.

d)

port 7 is used the HA heartbeat on all devices in the cluster.